Cloud/コネクタ/ログストリーミング

ログストリーミング

VinkiusについてAIに質問

このコネクタのログをリアルタイムで自分のシステムへ転送します。Splunk、Datadog、カスタムwebhookに対応し、宛先ごとに健全性、配信数、テスト結果を確認できます。

Log Streamingは、コネクタのAudit Logsの足跡を一歩先へ進めます。Vinkiusの外へ、チームがすでに監視しているシステムの中へ。サブタイトル:"Forward server logs to Splunk, Datadog, or custom webhooks."

R

Log Streaming

Forward server logs to Splunk, Datadog, or custom webhooks.

Add Destination
Security Ops SplunkSplunk
HealthyTest
1,204 delivered3 failuresLast success: Just now
HEC Token •••••••••••• → https://splunk.acme.com:8088

Real-time log streaming is available on Pro and Business plans.

Log Streaming, live. The destination with its health verdict, delivery counts and masked credentials, plus the Add Destination dialog switching between Splunk, Datadog and Webhook.

モックアップはBusinessアカウントでの実際のタブです。Add Destinationをクリックし、プロバイダーを切り替えて、クレデンシャルフィールドの変化を確認してみてください。

Businessの関門

これはBusinessプランの機能であり、それより低いプランではタブの代わりにカードが表示されます。Business Plan RequiredBUSINESS PLANのバッジ、説明"Log streaming is available on the Business plan. Upgrade to configure real-time log streaming to external providers"、そしてUpgrade to Businessボタンです。カードには得られるものが明記されています:"Real-time log streaming to Splunk, Datadog, or Webhook""90-day audit retention""Priority support with SLA"

宛先

Businessでは、タブは宛先ごとに1枚のカードを持ちます。名前、プロバイダー、そして配信の健全性の行。配信されたイベント、失敗、そしてLast successです。緑のHealthyの判定(または赤の逆)が、誰かのダッシュボードを開かなくてもパイプが生きていることを教えてくれます。クレデンシャルの行はマスクされたままです。SplunkのHEC Token、DatadogのAPI KeySite、またはwebhookのEndpoint URLとそのHMACのWebhook Secretです。

宛先の追加と信頼

Add Destinationを押すとダイアログが開きます。Name("My destination")、Providerのピル(Splunk、Datadog、Webhook)があり、選択に応じてクレデンシャルフィールドが変わります。各フィールドのヘルプテキストは、必要なものを正確に伝えます:"Your Splunk HTTP Event Collector token""Your Datadog API key for log intake""Your HMAC secret for webhook authentication." Testは配信を1回実行し、パイプに頼る前に判定(OKまたはFailed)を表示します。またDelete Destinationは、切断する前に確認を求めます。

このタブが存在する理由

ガバナンスのレポートはあなたが見る場所であり、ストリーミングはSOCがすでにいる場所です。イベントをSplunkやDatadogへ転送すれば、Vinkiusのテレメトリーが、コネクタごとに、あなたの保持期間、アラート、インシデントレビューの中に入ります。しかも、パイプ自体が機能していることを教えてくれる健全性の判定付きです。